Liquid Network holds real BitcoinBTC-- behind a token it sells as "1:1 backed." On September 6 someone moved 4,000 of its roughly 4,200 BTC out of the vault. The reassuring part of the story is the 85% that came back within a day. The material part is the ~$47 million that did not — and the fact that, three days later, nobody has said who is on the hook for it.
What "1:1 backed" actually meant before the weekend
Liquid is a sidechain launched by Blockstream in 2018: exchange-grade settlement infrastructure that a reader might reasonably have treated as boring plumbing. The bargain is simple. You send real Bitcoin into the network and receive L-BTC, a receipt redeemable one-for-one out of the federation's vault. The same vault backs other issued assets — USDT on Liquid, tokenized securities and real-world assets — because every L-BTC is supposed to represent a unit of real Bitcoin sitting in reserve.
That is the whole investment premise: a stated 1:1 cover, the way a chartered-company warehouse once promised that every paper receipt stood for a bar of metal in the cellar. The analogy holds exactly as long as the vault accounts are real and the redemption promise is honored. This weekend tested both.
Quick Backtesting Tool
The trace: how 4,000 BTC left a ~4,200-BTC vault
The exploit did not touch the keys that normally control the vault. It hit the validation software instead. Liquid runs on Blockstream's Elements codebase, which uses a privacy feature — "confidential transactions" with cryptographic range proofs — to prove that a user is not minting assets from nothing without revealing amounts. To save computing power, the software cached successful verification results. The bug was in how it identified those cached checks: it let invalid, unverified data point at a previously approved result.
In plain terms, the actors submitted valid data, had it cached as checked, then got affected nodes to accept different, invalid data against that same cached approval. That bypassed the check that keeps L-BTC backed by real Bitcoin — so they minted unbacked L-BTC and walked it out through the peg-out path into roughly 4,000 BTC, about 95% of the reserve, worth around $320 million at the time.
They did not run. They announced they were "white hats," said "we are whitehats, contact us on chain", and negotiated with Blockstream the only way two people who distrust a chat app would: messages written into the Bitcoin blockchain itself, PGP-encrypted in the transaction data field. Their stated condition for returning anything was that the bug be patched and every node updated. Blockstream replied on-chain that bridge nodes were fixed; a day after the theft, the actors sent 3,400 BTC — 85% of it — back to the federation.

The ~600 BTC no one has classified
The remaining ~598.5 BTC, worth about $47 million, did not come back. It sits in the actors' address as self-assigned change — a "finder's fee," in their telling, for pointing out the bug. That is where the tidy "white-hat" story starts to fray, because the size of that fee is exactly what they are now renegotiating in public.
Yesterday the group dropped the opaque PGP notes for plaintext, accused Blockstream of skimping on security, and demanded a 10% bounty paid from the company's own money. Press coverage is careful to call them "supposed" or "purported" white hats, and at least one security executive at a major wallet firm has argued that if the retention was a fee extracted under threat of keeping a hostage vault, it is closer to extortion than generosity. None of that is a legal finding; it is the competing read of the same moves. As of publication the network is still paused, its peg operations suspended, and Blockstream says discussions over the missing BTC continue.
Who actually eats the missing $47 million
The unresolved question for anyone holding L-BTC or a Liquid-issued asset is not whether the hackers had good intentions. It is which side of the balance sheet absorbs the shortfall. Run the ledger forward from today:
Before the weekend, L-BTC was a claim on a vault the federation said was fully covered. After it, roughly $47 million of backing is gone unless it is recovered or replaced. There are three ways this resolves, and they are not equal. Either the actors return the ~600 BTC, closing the hole; or Blockstream and the federation recapitalize the vault themselves, preserving the 1:1 promise and taking the loss on the company's own books; or the shortfall is absorbed by token holders, whose "1:1" cover quietly becomes a claim on a vault that is no longer full.
The distinction between the first two and the last one is the entire difference between a company absorbing a security failure and a custody customer silently eating it. That is the before/after table worth carrying, and as of publication no one has said which row applies. Blockstream is a private company, so there is no Liquid Network ticker to short or buy on the news — the investor stake runs through anyone whose positions are claims on this vault, and through the broader question of what "backed" now means for pegged assets everywhere.
The break condition
The story you have seen — "hackers returned 85%" — is technically true and strategically partial; 85% returned is the good-news cap on a breach that drained 95% of reserve and has left a contested $47 million hole with an unnamed bearer. The fact that would rewrite this read is an announced recapitalization, or a full return of the ~600 BTC, because either one moves the missing funds onto a balance sheet someone acknowledges owning. Until then, the honest position is that a "1:1 backed" token currently has its receipt-book under audit and its vault short — and no one, not the network and not the actors, has yet written down who is poor if the difference never arrives.













